Reporting

Why do I receive an "Unauthenticated senders not allowed" error when trying to send emails from Splunk?

mattstibbs
New Member

I am having trouble sending emails from Splunk. My colleague can send them without an issue, however when I try to send them I get the following error:

command="sendemail", (550, 'Unauthenticated senders not allowed', u'splunk@aaa.bbb.uk') while sending mail to: xxx.yyy@zzz.net

I am a power user and we can't find any other settings that would be preventing me from sending that differ to his (which work).

What are we missing?

Tags (4)
0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

You are getting a 550 SMTP error from your mail system (not Splunk). I would check the mail system you are pointed at when you try to send the message to determine the issue. Based on the message, the sending address may not be permitted to relay or to send to that recipient. It could also mean the address is not valid. Again, I would check the logs on the mail host at the time the message was sent to better troubleshoot the issue.

Jacob
Sr. Technical Support Engineer

mattstibbs
New Member

Thank you - we are using the generic configured email settings so I am ruling out there being any difference in settings between his use and mine.

I did find an article that suggested it might be because i don't have admin_all_objects permission - but that seems overkill just to send an email....

0 Karma

adonio
Ultra Champion

does your colleague uses the same splunk instance?

0 Karma

mattstibbs
New Member

yes - exactly the same

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...